Threat Hunter
2 weeks ago
We are the Microsoft 365 Defender team, and we are committed to defending Microsoft customers from sophisticated cyber-attacks and adversaries. Our mission is to help protect customers with truly innovative proactive approach, advising on emerging trends, and engaging in valuable partnerships. As the Research organization within Defender, it’s our job to stay one step ahead of malicious adversaries and predict the threats of the future. We work with partners across Microsoft to innovate new approaches for detecting and tracking threats, attacker techniques, their tools and infrastructure. We are always learning. Insatiably curious. We lean into uncertainty, take risks, and learn quickly from our mistakes. We build on each other’s ideas, because we are better together. Together we make a difference to all of our customers, from end-users to Fortune 50 enterprises. Our security products are brought together in the Microsoft 365 Defender (M365D) suite. M365D enables Microsoft’s enterprise customers to detect, investigate, understand, and respond to advanced threats on their networks via a combination of behavioral sensors, security analytics, and threat intelligence.
We are looking for Threat Hunters to join our endpoint hunting team. In this role you will use deep knowledge of the attacker landscape and rich telemetry from our sensors to perform root-cause analysis and generate custom alerts, ensuring that customers are well equipped to quickly respond to human adversaries identified in their unique environments. Ensuring that no human adversary can operate silently begins with experts harnessing the powerful optics provided by M365D, across the attacker kill-chain, coupled with world-class detections. We’re looking for a skilled hunters to harness the power of Microsoft’s trillions of security signals to quickly identify and report the latest human adversary behaviors, drive critical context-rich alerts, build new tools and automations in support of hunting objectives, and drive innovations for detecting advanced attacker tradecraft.
**Responsibilities**:
- Perform threat hunting on endpoints by exploring and correlating large data sets resulting in timely alerts for customers
- Uncover novel attack techniques, monitor and catalog changes in activity group tradecraft
- Acquire new and leverage existing knowledge of attacker tools, tactics and procedures to improve security posture of customers
- Effectively engage and collaborate with partners in data science, threat research to develop and maintain high-fidelity detection rules
- Build or identify hunting tools and automations for use in the discovery of human adversaries
**Qualifications**:
- Degree in Computer Science or a related technical discipline
- 5+ years of computer security industry experience in a technical role such as Security Operations, Malware analysis, Threat Intelligence, Cyber Incident Response, or Penetration Testing/Red Team
- 1+ years of coding and scripting experience (Regex, Python, SQL, KQL)
- Comfortable working with large data sets for analysis and visualization, using tools and scripting languages such as: Excel, SQL, Python, Splunk Query Language, Kusto query language, Jupyter Notebooks and PowerBI
- Functional understanding of common threat analysis models such as Cyber Kill Chain, MITRE ATT&CK
- Ability to track, analyze, and brief on new and ongoing cyber-attacks with understanding of identity and popular authentication/authorization protocols
- Experience using analysis tools (e.g. file/network/OS monitoring tools and/or debuggers) and knowledge of operating system internals and security mechanisms
- Experience in endpoint protection technologies such as EPP/EDR (e.g. Microsoft Defender for Endpoint)
- Experience with reverse engineering, digital forensics (DFIR) or incident response, or machine learning models
- Experience with offensive security including tools such as Metasploit, exploit development, Open Source Intelligence Gathering (OSINT), and designing ways to breach enterprise networks
- Experience with advanced persistent threats and human adversary compromises
- Broad, general familiarity with the threat landscape affecting enterprise customers
- Good verbal and written communication skills in English
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
-
M365d - Threat Hunter
2 weeks ago
Hyderabad, India Microsoft Full timeM365D - Threat Hunter Who we are: We are the Microsoft 365 Defender team, and we are committed to defending Microsoft customers from sophisticated cyber-attacks and adversaries. Our mission is to help protect customers with truly innovative proactive approach, advising on emerging trends, and engaging in valuable partnerships. As the Research organization...
-
Threat Hunter
2 weeks ago
Hyderabad/ Secunderabad, India Dell Technologies Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description Secureworks (NASDAQ: SCWX) a global cybersecurity leader, enables our customers and partners to outpace and outmaneuver adversaries with more precision, so they can rapidly adapt and respond to market forces to meet their business needs. With a unique combination of cloud-native, SaaS security platform and intelligence-driven security...
-
M365d Threat Hunter
2 weeks ago
Hyderabad, India Microsoft Full timeWe are the Security, Compliance and Management (S+C+M) team; we are committed to defending Microsoft customers from cyber-attacks as well as providing sophisticated tooling for securing important data. S+C fosters an agile development environment, continuously gathering and analyzing data to combat evolving threats. Our mission is to help protect customers...
-
M365 Threat Hunter
2 weeks ago
Hyderabad, India Microsoft Full timeAre you interested in working on the cutting edge of enterprise security products? Do you want to combat evolving, advanced security threats? Do you want to help shape intelligence and analytics systems powering one of the most advanced security products Microsoft offers today? Microsoft 365 Defender Suite is the unified suite that enables Microsoft’s...
-
Threat Hunter Ii
2 weeks ago
Hyderabad, Telangana, India Microsoft Full timeSecurity represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified...
-
Threat Hunter 2
2 weeks ago
Hyderabad, Telangana, India Microsoft Full timeSecurity represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified...
-
M365d - Threat Researcher
2 weeks ago
Hyderabad, India Microsoft Full timeWe are the Security, Compliance and Management (S+C+M) team; we are committed to defending Microsoft customers from cyber-attacks as well as providing sophisticated tooling for securing important data. S+C fosters an agile development environment, continuously gathering and analyzing data to combat evolving threats. Our mission is to help protect customers...
-
SOC L3
4 days ago
Madhapur, Hyderabad, Telangana, India Locuz Enterprise Solutions Full time**SOC Lead Threat Hunter** - Around 8-10 years working experience in Global SOC - Must have experience in any SIEM Management tool Splunk, QRADAR, HP Arc sight, - Triage Specialist - Separating the wheat from the chaff. - Vulnerability Management tools like Tenable, Rapid 7, Qualys, Nmap, Brupsuite etc.. - Experience in conducting VA/PT of Infrastructure and...
-
Associate Director, Threat Hunter
6 days ago
Hyderabad, Telangana, India HSBC Full timeJob description Some careers shine brighter than others If you re looking for a career that will help you stand out join HSBC and fulfil your potential Whether you want a career that could take you to the top or simply take you in an exciting new direction HSBC offers opportunities support and rewards that will take you further HSBC is one of the largest...
-
Platform Engineer
2 weeks ago
Hyderabad, Telangana, India Emperen Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per yearAbout the Role:Duration: 6 monthsTimings: Full Time (As per company timings)Shift: General Shift, Cab facility is available. 5 days work from the office.Notice Period: (Immediate Joiner - Only)Responsibilities:Design and develop detection rules and policies to identify cybersecurity threats across various platforms and technologies.Lead the design,...